Redirect hack - Joomla! Forum - community, help and support


hello all. have read sticky, , following instructions properly. started off .htaccess file redirect, .htaccess file rewritten every 5 ten minutes. sites looked fine until searching them via search engine, clicking visit. started deleting sites 1 one until .htaccess stopped being changed. i'm not sure site offending site, .htaccess doesn't change anymore. 1 of sites still suffering redirect now, , can't determine if because there trouble .htaccess (i don't think so) or buried script causing me grief. believe extensions not on vulnerable list, i'm not sure 1 of jce extensions i'm running. also, believe of permissions incorrect, , i'm not sure how change them in bulk. thank in advance.

forum post assistant (v1.2.3) : 6th november 2012 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.7-stable (ember) 13-september-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | read-only (444) | owner: u45447092 (uid: 1/gid: 1) | group: ftpusers (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 0 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes

host configuration :: os: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | os version: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | technology: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | web server: apache | encoding: gzip, deflate | doc root: /kunden/homepages/34/d207339782/htdocs/veritascatholicschool.ca | system tmp writable: yes

php configuration :: version: 5.2.17 | php api: cgi-fcgi | session path writable: unknown | display errors: 1 | error reporting: 6135 | log errors to: | last known error: | register globals: 0 | magic quotes: 0 | safe mode: 0 | open base: /homepages/34/d207339782/htdocs:/tmp | uploads: 1 | max. upload size: 2m | max. post size: 8m | max. input time: -1 | max. execution time: 30 | memory limit: 128m

mysql configuration :: version: 5.0.91-log (client:5.1.49) | host: --protected-- (--protected--) | collation: latin1_general_ci (character set: latin1) | database size: 542.03 kib | #of tables: 96
detailed environment :: wrote:php extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dba () | dbase () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | session () | iconv () | idn () | standard (5.2.17) | json (1.2.1) | mbstring () | mcrypt () | mhash () | mysql (1.0) | simplexml (0.1) | spl (0.2) | pdo (1.0.4dev) | pdo_sqlite (1.0.1) | posix () | reflection (0.1) | imap () | shmop () | pdo_mysql (1.0.2) | soap () | mysqli (0.1) | sqlite (2.0-dev) | exif (1.4 $id: exif.c 293036 2010-01-03 09:23:27z sebastian $) | tidy (2.0) | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlwriter (0.1) | xsl (0.1) | zip (1.8.11) | cgi-fcgi () | zend engine (2.2.0) |
potential missing extensions :: suhosin |

switch user environment (experimental) :: php cgi: yes | server su: no | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) ::
extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) | default (1.0.0) | wf_aggregator_vimeo_title (2.2.8.4) | [youtube] (2.2.8.4) | wf_filesystem_joomla_title (2.2.8.4) | wf_links_joomlalinks_title (2.2.8.4) | wf_mediaplayer_jceplayer_title (2.2.8.4) | wf_popups_jcemediabox_title (2.2.8.4) | wf_popups_window_title (2.2.8.4) | wf_link_search_title (2.2.8.4) | wf_anchor_title (2.2.8.4) | wf_article_title (2.2.8.4) | wf_autosave_title (2.2.8.4) | wf_browser_title (2.2.8.4) | wf_cleanup_title (2.2.8.4) | wf_clipboard_title (2.2.8.4) | wf_contextmenu_title (2.2.8.4) | wf_directionality_title (2.2.8.4) | wf_fullscreen_title (2.2.8.4) | wf_imgmanager_title (2.2.8.4) | wf_inlinepopups_title (2.2.8.4) | [do not buy our kitchens!] (2.2.8.4) | wf_layer_title (2.2.8.4) | wf_link_title (2.2.8.4) | wf_media_title (2.2.8.4) | wf_nonbreaking_title (2.2.8.4) | wf_preview_title (2.2.8.4) | wf_print_title (2.2.8.4) | wf_searchreplace_title (2.2.8.4) | wf_source_title (2.2.8.4) | wf_spellchecker_title (2.2.8.4) | wf_style_title (2.2.8.4) | wf_table_title (2.2.8.4) | wf_textcase_title (2.2.8.4) | wf_visualblocks_title (2.2.8.4) | wf_visualchars_title (2.2.8.4) | wf_xhtmlxtras_title (2.2.8.4) |
components :: admin :: com_admin (2.5.0) | com_banners (2.5.0) | com_cache (2.5.0) | com_categories (2.5.0) | com_checkin (2.5.0) | com_config (2.5.0) | com_content (2.5.0) | com_cpanel (2.5.0) | com_finder (2.5.0) | com_installer (2.5.0) | jevents (2.2.3) | com_joomlaupdate (2.5.0) | com_languages (2.5.0) | com_login (2.5.0) | com_media (2.5.0) | com_menus (2.5.0) | com_messages (2.5.0) | com_modules (2.5.0) | com_newsfeeds (2.5.0) | com_plugins (2.5.0) | com_redirect (2.5.0) | com_search (2.5.0) | com_templates (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) | com_phocagallery (3.2.1) | unknown (-) | editor - jce (2.2.8.4) | editor - jce (2.2.8.4) | jce file browser (2.0.0) | plg_quickicon_jcefilebrowser (2.5.0) | jce (2.2.8.4) | akeeba (3.6.7) |

modules :: site :: mod_articles_archive (2.5.0) | mod_articles_categories (2.5.0) | mod_articles_category (2.5.0) | mod_articles_latest (2.5.0) | mod_articles_news (2.5.0) | mod_articles_popular (2.5.0) | mod_banners (2.5.0) | mod_breadcrumbs (2.5.0) | mod_custom (2.5.0) | mod_feed (2.5.0) | mod_finder (2.5.0) | mod_footer (2.5.0) | jevents calendar (2.2.0) | jevents filter (2.2.0) | latest jevents (2.2.0) | jevents legend (2.2.3) | mod_languages (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_random_image (2.5.0) | rapid contact (1.2) | mod_related_items (2.5.0) | mod_search (2.5.0) | mod_stats (2.5.0) | mod_syndicate (2.5.0) | mod_users_latest (2.5.0) | mod_weblinks (2.5.0) | mod_whosonline (2.5.0) | mod_wrapper (2.5.0) |
modules :: admin :: mod_custom (2.5.0) | mod_feed (2.5.0) | mod_latest (2.5.0) | mod_logged (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_multilangstatus (2.5.0) | mod_popular (2.5.0) | mod_quickicon (2.5.0) | mod_status (2.5.0) | mod_submenu (2.5.0) | mod_title (2.5.0) | mod_toolbar (2.5.0) | mod_version (2.5.0) |

plugins :: site :: plg_authentication_gmail (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_content_emailcloak (2.5.0) | plg_content_finder (2.5.0) | plg_content_geshi (2.5.0) | plg_content_joomla (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_vote (2.5.0) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.4.1) | editor - jce (2.2.8.4) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_extension_joomla (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_contacts (2.5.0) | plg_finder_content (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_weblinks (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_quickicon_jcefilebrowser (2.5.0) | plg_search_categories (2.5.0) | plg_search_contacts (2.5.0) | plg_search_content (2.5.0) | search - jevents (2.2.0) | plg_search_newsfeeds (2.5.0) | plg_search_weblinks (2.5.0) | plg_system_cache (2.5.0) | plg_system_debug (2.5.0) | plg_system_highlight (2.5.0) | ja t3 framework (2.5.6) | plg_system_languagecode (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_log (2.5.0) | plg_system_logout (2.5.0) | plg_system_p3p (2.5.0) | plg_system_redirect (2.5.0) | plg_system_remember (2.5.0) | plg_system_sef (2.5.0) | plg_user_contactcreator (2.5.0) | plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_jmonitoring_akeebabackup_t (1.0) |
templates discovered :: wrote:templates :: site :: atomic (2.5.0) | beez5 (2.5.0) | beez_20 (2.5.0) | business11 (1.0.1) | business12 (2.5.1) | ecoplanet-fts (2.5.0) | webx (2.5.0) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |

i have update problem. seems based on javascript hack. when replace infected .js files, written on infected files.

any ideas?





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support